{"id":"CVE-2026-88402","published":"2026-09-21T21:17:14.273","lastModified":"2026-09-22T20:00:03.713","description":"A SQL injection vulnerability in the checkSQL function of nocobase v2.1.21 allows attackers to access sesntive database information via injecting crafted SQL statements.","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-89"],"vendors":[],"products":[],"references":[{"url":"https://github.com/czx1111/cve/issues/6","tags":[]},{"url":"https://github.com/czx1111/cve/issues/6","tags":[]}],"exploitRefs":[{"url":"https://github.com/czx1111/cve/issues/6","tags":[]},{"url":"https://github.com/czx1111/cve/issues/6","tags":[]}],"hasPoc":true,"ai":{"summary":"A SQL injection vulnerability in nocobase v2.1.21 enables attackers to access sensitive database information by injecting malicious SQL statements, posing a critical risk.","exploitability":"Exploitation is relatively straightforward given the vulnerability, requiring attackers to inject crafted SQL statements via specific input fields.","blast_radius":"If exploited, attackers could gain full access to the database, leading to data breaches and potential loss of sensitive information.","remediation":"Upgrade to nocobase v2.1.22 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["sql-injection","database","web"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:59:35.884Z"}}